Chapter 3

Learning Is FUNdamental!

As it turns out, throwing technology at defective software is likely the worst way to address appsec and ignores the basic tenet—software security is a human factors issue, not a technical issue. Tools are seductive with their coolness factor, ease of acquisition and use, and producing quick results that—in fact—tell you that you do have an issue with software security. Taking tools to the next step is where things quickly fall apart.

Suddenly, development teams are bombarded by reams of proof that their software is defective, and with finger-pointing from security teams, they’re left in a state of upset and overall chaos. Furthermore, these development team members often don’t understand what this proof ...

Get Secure, Resilient, and Agile Software Development now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.